


Tim Johns, Vice President Information Technology, at Custard Insurance Adjusters, has built a career over four decades, witnessing firsthand the transformation of IT and cybersecurity. From working with mainframes and punch cards in the early 1980s to leading IT security strategy for a major insurance adjuster, his journey is a testament to adaptability and leadership in a rapidly evolving digital world.
In this interview with Insurance CIO Outlook Latin America, Johns shares insights into today’s biggest cybersecurity challenges, industry trends, the role of vendor risk management and the importance of leadership buy-in for effective security strategies. He also discusses the human factor in cybersecurity and why proactive security measures must be a priority for every organization.
A Career Defined by Technological Shifts
My journey in IT started in high school when I was introduced to keypunch operations and punch cards, both of which were foundational in financial institutions at the time. I began my professional career in mainframe computing, spending seven years mastering its complexities before transitioning into server technology as the industry evolved.
By the late 1980s, Microsoft was starting to disrupt the IT space. Initially, I was skeptical that PC technology could replace mainframes, but it quickly became evident that the industry was shifting. I adapted by moving into client-server technology in 1990. At that time, Novell dominated networking, and I became a Microsoft-certified systems engineer (MCSE) in 1996.
My career took me across multiple industries, from medical records management—where I led a team overseeing 60 million medical records—to healthcare IT, finance and legal operations. Eventually, I joined Custard Insurance Adjusters as an IT Manager, a role comparable to an IT Director in many companies. Over time, my leadership in IT strategy and cybersecurity led to my promotion as vice president of IT Operations and chief information security officer (CISO), where I now oversee enterprise security, IT governance and risk management.
From Paper Credentials to Real-World Readiness
One of the biggest challenges in cybersecurity today is the shortage of skilled professionals. Many candidates look great on paper, but they fall short when it comes to hands-on experience. Certifications and formal education are helpful but don’t always translate into the expertise needed to handle real-world threats.
High salary expectations further complicate the issue. While cybersecurity roles demand competitive compensation, companies struggle to find candidates who justify the investment. I’ve interviewed many people who list cybersecurity skills on their resumes but lack the depth needed to operate in a high-stakes environment.
Another challenge is getting leadership buy-in. Many organizations only prioritize cybersecurity after experiencing a breach, which is often too late. At Custard Insurance Adjusters, we’re fortunate to have leadership that understands the importance of integrating cybersecurity into business processes rather than treating it as an afterthought. This commitment helps us reduce risk exposure and align security efforts with broader business objectives.
“Cybersecurity is not a one-time initiative—it requires ongoing investment, skill development and cultural integration.”
Despite increased awareness, many companies remain reactive rather than proactive in their cybersecurity strategies. The rise of ransomware, supply chain vulnerabilities and cloud security risks has made cyber resilience a necessity. Unfortunately, some organizations delay investment in cybersecurity until they experience an attack, leading to costly consequences.
A strong cybersecurity strategy should be proactive and incorporate continuous threat intelligence, security monitoring and risk management. At Custard Insurance Adjusters, we focus on staying ahead of threats by leveraging security intelligence and industry best practices. Regular security assessments and governance frameworks help us ensure that our defenses remain effective against evolving cyber risks.
Closing the Cybersecurity Gaps
Cybersecurity isn’t just about protecting internal systems—it also requires securing the third-party vendors we rely on. Many breaches happen due to vulnerabilities in a company’s supply chain, where attackers exploit weak security measures in vendor systems.
At Custard Insurance Adjusters, we take vendor risk management seriously. We assess our partners’ compliance with security regulations, conduct regular audits and implement strict access controls. A key example was a recent vulnerability found in Fortinet’s VPN software. When the security flaw was disclosed, we immediately patched our firewalls. Shortly after, we detected suspicious activity, but because we had already applied the patch, we prevented what could have been a serious breach. This reinforced the importance of staying ahead of threats through constant monitoring and prompt action.
Technology is crucial in strengthening security, but it’s only effective when combined with firm policies and employee awareness. At Custard Insurance Adjusters, we’ve integrated AI-driven security analytics, machine learning and automated threat detection into our operations. These tools help us identify and mitigate threats before they escalate.
However, technology alone isn’t enough. Employees are often the first line of defense, and without proper training, they can inadvertently expose the company to cyber risks. We conduct regular security awareness programs to educate our teams on phishing attacks, social engineering and other cyber threats. A strong security culture is just as important as the tools we deploy.
Regular security audits and penetration testing help us avoid potential threats, ensuring that vulnerabilities are identified and addressed before attackers can exploit them.
Cybersecurity is not a one-time initiative—it requires ongoing investment, skill development and cultural integration. For an organization to be resilient, security must be embedded into every aspect of business operations.
At Custard Insurance Adjusters, security isn’t just an IT function—it’s a business enabler. By integrating cybersecurity into decision-making processes, we ensure that security initiatives align with operational goals and long-term business continuity.
The Next Era of Cybersecurity Starts Now
Cyber threats are becoming more complex, requiring organizations to remain agile and proactive. Predictive security models will define the future of cybersecurity leadership, where organizations anticipate threats before they materialize. AI and automation will be crucial in managing large-scale security operations efficiently.
Regulatory compliance and data privacy laws will also shape security strategies. Companies that fail to stay ahead of emerging regulations risk financial and reputational damage. At Custard Insurance Adjusters, we’re committed to continuous improvement, adapting our cybersecurity strategy to align with evolving threats and compliance standards.
Cybersecurity is no longer optional—it’s a necessity for business survival. Organizations that invest in proactive security measures today will thrive in the future. At Custard Insurance Adjusters, we remain committed to building a resilient cybersecurity framework by staying ahead of threats, strengthening vendor risk management and fostering a culture of security awareness.
By prioritizing strategic leadership and continuous improvement, we ensure that our organization remains secure, competitive and prepared for the ever-changing digital landscape.